> He just doesn't like everybody uses JWT instead of cookie in any case.
Why would anybody care about how you implement something in your application, unless they have a concrete reason that your implementation is less than ideal?
> What you need to do if the redis server cannot support so many users?
Scale up your infrastructure. You're need a LOT of users before this starts being an issue.
> So use JWT to keep stateless is a good choice.
The article explains why this is a bad idea... unless you can explain where the article is wrong?
EDIT: Got caught in the middle of a thought, apologies.
StartCom are well known for their misunderstanding of how TLS works (see: the heartbleed revocation bull), and... this apparently costs money?
IIRC StartCom also used to generate private keys on their servers... They're utterly incompetent.